Unverified Password Change Vulnerability in Modicon PLCs by Schneider Electric
CVE-2018-7811
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 30 November 2018
What is CVE-2018-7811?
The vulnerability exists in the embedded web servers of various Modicon PLCs, allowing an unauthenticated remote user to exploit the system by accessing the change password function. This can potentially lead to unauthorized modifications and access to sensitive operational functions, thereby jeopardizing the security of the entire automation system. Mitigation strategies should be employed to secure web server access and ensure user authentication.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved